In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.